See the AI estate before you try to govern it
This demo runs the first phase of the AI Governance Readiness service. The customer’s pre-work and existing evidence go through seven agents, the Governance Analyzer; a person reviews the critical calls; the outputs match the project deliverables.
Three questions it answers
What AI is actually in use?Systems, sanctioned tools, personal accounts, IDE agents.
What code and data can leave?Source code, keys, logs and player data reaching external AI.
What must be governed first?What needs containment, an owner, or more evidence.
How to read the results
FACT Confirmed by a specific evidence source
ASSUMPTION Likely, but needs confirmation
UNKNOWN Not yet known. Tracked with an owner, never treated as safe
Fictional scenario. Arenal Play and all evidence are synthetic. Not monitoring, certification or legal advice. Optional add-ons, scoped separately: technical discovery and assurance testing.
Evidence in, decisions out
- 1Evidence firstEvery finding cites its source.
- 2Rules before the modelRules find signals; the model classifies them.
- 3Agents propose, people decideYou confirm each critical and high condition.
- 4Unknowns stay visibleEach gets an owner and a due date.
Every condition follows one chain: FACT → EVIDENCE → OWNER → DECISION → NEXT GATE.
| Governance Analyzer agent | Produces | How |
|---|---|---|
| 1. Evidence intake | Evidence register and coverage | Deterministic |
| 2. Shadow AI discovery | AI signals with source and basis | Rules + model |
| 3. Inventory and ownership | AI estate register, declared vs discovered | Model |
| 4. Risk and conditions | Owned conditions with next gate | Model |
| 5. Control mapping | Controls mapped to NIST AI RMF | Model |
| 6. Governance review | Your rating and disposition | Human |
| 7. Roadmap and scorecard | 0–4 scorecard, roadmap, proposed disposition | Model + rule |
Same workflow, pre-built or live
| Step | Demo mode | Live mode (Claude or OpenAI) |
|---|---|---|
| Evidence | Synthetic samples | Same samples; only sources in scope are sent |
| Model-driven agents | Pre-built outputs | One validated JSON call per agent |
| Governance review | You decide | You decide |
| If a step fails | — | Falls back to pre-built output, clearly labeled |
See exactly what the model sees
On the Agent workflow tab, Prompt and response shows each agent’s prompt, guardrails, raw response and validation.
Keys and data
- Your key stays in this tab’s memory and goes only to the provider you picked. Use one with a spending limit.
- Synthetic data only. Never paste customer evidence.
- Live mode needs the file opened locally or from a web host such as GitHub Pages.
Walking a customer through it
| Audience | Time | Path |
|---|---|---|
| Executive sponsor | 5 min | Run, accept the review, walk Deliverables 01–06. |
| Mixed room | 10 min | Show two evidence samples, step through agents, override one decision. |
| Engineering and security | 20 min | Run live with Claude or OpenAI and open Prompt and response. |
Three moments worth showing
Declared vs discoveredPre-work declared 5 AI assets; the evidence shows 13.
Pre-work example presetPartial evidence turns facts into assumptions and adds UNKNOWNs.
Block / pause R1 tooThe proposed disposition changes to “Remediate”.
1–4 switch tabs · R run · N next agent
Evidence sources
The customer’s pre-work plus nine kinds of evidence most organizations already hold. Mark each source available, partial or not available, as the pre-work evidence map does.